rssh Command Line Filtering Multiple Remote Arbitrary Command Execution Vulnerabilities
BID:56708
Info
rssh Command Line Filtering Multiple Remote Arbitrary Command Execution Vulnerabilities
| Bugtraq ID: | 56708 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2251 CVE-2012-2252 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2012 12:00AM |
| Updated: | Apr 13 2015 09:55PM |
| Credit: | James Clawson |
| Vulnerable: |
rssh rssh 2.3.3 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: |
rssh rssh 2.3.4 |
Discussion
rssh Command Line Filtering Multiple Remote Arbitrary Command Execution Vulnerabilities
rssh is prone to multiple remote arbitrary command-execution vulnerabilities because it fails to correctly filter command line options.
An attacker can exploit these issues to execute arbitrary commands within the context of the vulnerable application.
rssh is prone to multiple remote arbitrary command-execution vulnerabilities because it fails to correctly filter command line options.
An attacker can exploit these issues to execute arbitrary commands within the context of the vulnerable application.
Exploit / POC
rssh Command Line Filtering Multiple Remote Arbitrary Command Execution Vulnerabilities
Attackers can use readily available tools to exploit these issues.
Attackers can use readily available tools to exploit these issues.
Solution / Fix
rssh Command Line Filtering Multiple Remote Arbitrary Command Execution Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
rssh Command Line Filtering Multiple Remote Arbitrary Command Execution Vulnerabilities
References:
References:
- rssh Product Page (rssh)
- rssh: incorrect filtering of command line options (SECLISTS)